
Automatisiert Windows-Speicherforensik und DFIR-Workflows mit MemProcFS: YARA/ClamAV-Scans, Erkennung von Prozessanomalien sowie Artefakt- und Log-Extraktion.
MemProcFS-Analyzer.ps1 ist ein PowerShell-Skript, das die Verwendung von MemProcFS vereinfacht und Ihren Speicheranalyse-Workflow optimiert.
MemProcFS - Das Memory Process File System von Ulf Frisk
https://github.com/ufrisk/MemProcFS
Funktionen:
Laden Sie die neueste Version von MemProcFS-Analyzer aus dem Bereich Releases herunter.
Starten Sie Windows PowerShell (oder Windows PowerShell ISE oder Visual Studio Code mit PSVersion: 5.1) als Administrator und öffnen/führen Sie MemProcFS-Analyzer.ps1 aus.
File-Browser
Abb. 1: Wählen Sie Ihren Speicher-Snapshot und wählen Sie Ihre pagefile.sys (optional)
Auto-Install
Abb. 2: MemProcFS-Analyzer installiert Abhängigkeiten automatisch (erster Start)

Abb. 3: Nutzungsbedingungen akzeptieren (erster Start)
MemProcFS
Abb. 4: Wenn Sie MemProcFS nützlich finden, werden Sie bitte Sponsor unter: https://github.com/sponsors/ufrisk

Abb. 5: Sie können das gemountete Speicherabbild untersuchen, indem Sie den Laufwerksbuchstaben erkunden
Auto-Update
Abb. 6: MemProcFS-Analyzer sucht nach Updates (zweiter Start)
Hinweis: Es wird empfohlen, die Funktion „Updater“ nach der Installation auszukommentieren/deaktivieren. Beachten Sie den Abschnitt „Main“ am unteren Ende des Skripts.

Abb. 7: FindEvil-Funktion und zusätzliche Analysen

Abb. 8: Prozesse

Abb. 9: Laufende und beendete Prozesse

Abb. 10: Process Tree (GUI)

Abb. 11: Process Tree prüfen (um Anomalien zu finden)

Abb. 12: Process Tree: Alarmmeldungen mit Process Call Chain

Abb. 13: Process Tree: Eigenschaftenansicht → Doppelklicken Sie auf einen Prozess oder eine Alarmmeldung

Abb. 14: GeoIP mit IPinfo.io

Abb. 15: IPs mit IPinfo.io kartieren
EVTX
Detections
Abb. 16: Verarbeitung von Windows-Ereignisprotokollen (EVTX)

Abb. 17: Zircolite – Ein eigenständiges, SIGMA-basiertes Erkennungstool für EVTX (Mini-GUI)

Abb. 18: Verarbeitung der extrahierten Amcache.hve → XLSX

Abb. 19: Verarbeitung von ShimCache → XLSX

Abb. 20: CSV-Ausgabe mit Timeline Explorer (TLE) analysieren

Abb. 21: ELK-Import

Abb. 22: Viel Spaß bei der ELK-Jagd!

Abb. 23: Multithread-ClamAV-Scan, der Ihnen hilft, Böses zu finden! ;-)

Abb. 24: Drücken Sie OK, um MemProcFS und Elastisearch/Kibana herunterzufahren

Abb. 25: Secure Archive Container (Passwort: MemProcFS)
Schauen Sie sich Super Easy Memory Forensics von Hiroshi Suzuki und Hisao Nashiwa an.
Laden Sie das neueste Dokany Library Bundle herunter und installieren Sie es → DokanSetup.exe
https://github.com/dokan-dev/dokany/releases/latest
Laden Sie die neueste .NET 9 Desktop Runtime herunter und installieren Sie sie (Voraussetzung für EZTools)
https://dotnet.microsoft.com/en-us/download/dotnet/9.0
Laden Sie das neueste Windows-Paket von ClamAV herunter und installieren Sie es.
https://www.clamav.net/downloads#otherversions
Ersteinrichtung von ClamAV
Starten Sie die Windows-PowerShell-Konsole als Administrator.
cd "C:\Program Files\ClamAV"
copy .\conf_examples\freshclam.conf.sample .\freshclam.conf
copy .\conf_examples\clamd.conf.sample .\clamd.conf
write.exe .\freshclam.conf → Kommentieren Sie die Zeile mit „Example“ aus oder entfernen Sie sie.
write.exe .\clamd.conf → Kommentieren Sie die Zeile mit „Example“ aus oder entfernen Sie sie.
https://docs.clamav.net/manual/Usage/Configuration.html#windows
Optimieren Sie die Scan-Geschwindigkeit von ClamAV (30 % schneller)
Öffnen Sie „C:\Program Files\ClamAV\clamd.conf“ mit Ihrem Texteditor und suchen Sie nach: „Don't scan files and directories matching regex“
ExcludePath "\\heaps\\"
Hinweise:
1768.py v.0.0.23 (2025-03-07)
https://blog.didierstevens.com/?s=1768.py
7-Zip 26.00 Standalone Console (2026-02-12)
https://www.7-zip.org/download.html
AmcacheParser v2026.5.0.0 (.NET 9)
https://ericzimmerman.github.io/
AppCompatCacheParser v2026.5.0.0 (.NET 9)
https://ericzimmerman.github.io/
ClamAV - Download → Windows → clamav-1.5.2.win.x64.msi (2026-03-04)
https://www.clamav.net/downloads
Dokany Library Bundle v2.3.1.1000 (2025-09-28)
https://github.com/dokan-dev/dokany/releases/latest → DokanSetup.exe
Elasticsearch 9.3.4 (2026-04-30)
https://www.elastic.co/downloads/elasticsearch
entropy v1.1 (2023-07-28)
https://github.com/merces/entropy
EvtxECmd v2026.5.0.0 (.NET 9)
https://ericzimmerman.github.io/
ImportExcel v7.8.10 (2024-10-21)
https://github.com/dfinke/ImportExcel
IPinfo CLI 3.3.2 (2026-04-28)
https://github.com/ipinfo/cli
jq v1.8.1 (2025-07-01)
https://github.com/stedolan/jq
Kibana 9.3.4 (2026-04-30)
https://www.elastic.co/downloads/kibana
lnk_parser v0.4.3 (2026-02-17)
https://github.com/AbdulRhmanAlfaifi/lnk_parser
MemProcFS v5.17.6 – Das Memory Process File System (2026-04-19)
https://github.com/ufrisk/MemProcFS
RECmd v2026.5.0.0 (.NET 9)
https://ericzimmerman.github.io/
SBECmd v2026.5.0.0 (.NET 9)
https://ericzimmerman.github.io/
xsv v0.13.0 (2018-05-12)
https://github.com/BurntSushi/xsv
YARA v4.5.5 (2025-10-30)
https://virustotal.github.io/yara/
Zircolite v3.6.3 (2026-04-06)
https://github.com/wagga40/Zircolite
MemProcFS
Demo von MemProcFS mit Elasticsearch
Sponsor des MemProcFS-Projekts
MemProcFS-Plugins
ExcludePath "\\handles\\"ExcludePath "\\memmap\\vad-v\\"ExcludePath "\\sys\\pool\\"Erstellen Sie Ihr kostenloses IPinfo-Konto [ca. 1–2 Minuten]
https://ipinfo.io/signup?ref=cli
Öffnen Sie „MemProcFS-Analyzer.ps1“ mit Ihrem Texteditor, suchen Sie nach „Please insert your Access Token here“ und kopieren/fügen Sie Ihr Zugriffstoken ein.
Stellen Sie sicher, dass Sie die Funktionen, mit denen Sie arbeiten möchten, auskommentieren/einkommentieren (selektiv aktivieren oder deaktivieren) (Elasticsearch und ELKImport sind standardmäßig deaktiviert). Schauen Sie sich das „Main“ am Ende des Skripts an.
Starten Sie den automatisierten Installer/Updater für MemProcFS-Analyzer
.\Updater.ps1
Installieren Sie Python 3.x (und aktivieren Sie das Kontrollkästchen „Add Python 3.x to PATH“).
Installieren Sie die Abhängigkeiten für Zircolite:
cd .\Tools\Zircolite
python -m pip install --upgrade pip
python -m pip install -r requirements.txt
Fertig! 😃